Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Umbraco Identity Extensibility MEDIUM 5.3
CVE-2023-32312

UmbracoIdentityExtensions is an Umbraco add-on package that enables easy extensibility points for ASP.Net Identity integration. In affected versions …

Fix: after 2.0.0
Fix from $1,600 2023-06-09
Tgstation Server MEDIUM 5.3
CVE-2023-34243

TGstation is a toolset to manage production BYOND servers. In affected versions if a Windows user was registered in tgstation-server (TGS), an attack…

Fix: 5.12.5+
Fix from $1,600 2023-06-08
Cics Tx MEDIUM 6.5
CVE-2023-33848

IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could allow a privileged user to obtain highly…

Mitigation only
Fix from $1,600 2023-06-07
Doneren Met Mollie MEDIUM 6.5
CVE-2021-4377

The Doneren met Mollie plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.8.5 via the dmm_export_donat…

Fix: after 2.8.5
Fix from $1,600 2023-06-07
Listingpro MEDIUM 5.3
CVE-2020-36723

The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions before 2.6.1 via the ~/listin…

Fix: 2.6.1+
Fix from $1,600 2023-06-07
9205 Lte Modem Firmware MEDIUM 5.5
CVE-2022-40523

Information disclosure in Kernel due to indirect branch misprediction.

Mitigation only
Fix from $1,600 2023-06-06
Csr8811 Firmware MEDIUM 5.5
CVE-2022-40525

Information disclosure in Linux Networking Firmware due to unauthorized information leak during side channel analysis.

No fix yet
Fix from $1,600 2023-06-06
Wordpress Exit Box Lite HIGH 7.5
CVE-2013-10030

A vulnerability, which was classified as problematic, has been found in Exit Box Lite Plugin up to 1.06 on WordPress. Affected by this issue is some …

Fix: after 1.06
Fix from $1,950 2023-06-05
Kanboard MEDIUM 6.5
CVE-2023-33956

Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are subject to an Insecure direc…

Fix: 1.2.30+
Fix from $1,600 2023-06-05
Amxgt 100 MEDIUM 5.3
CVE-2023-3064

Anonymous user may get the list of existing users managed by the application, that could ease further attacks (see CVE-2023-3065 and 3066)This issue …

Fix: after 1.3.20
Fix from $1,600 2023-06-05
Chuanhuchatgpt MEDIUM 5.3
CVE-2023-34094

ChuanhuChatGPT is a graphical user interface for ChatGPT and many large language models. A vulnerability in versions 20230526 and prior allows unauth…

Fix: after 2023-05-26
Fix from $1,600 2023-06-02
Splunk MEDIUM 5.3
CVE-2023-32710

In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and in Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can pe…

Fix: 8.1.14 / 8.2.11+
Fix from $1,600 2023-06-01
Openproject HIGH 7.5
CVE-2023-33960

OpenProject is web-based project management software. For any OpenProject installation, a `robots.txt` file is generated through the server to denote…

Fix: 12.5.6+
Fix from $1,950 2023-06-01
Vite HIGH 7.5
CVE-2023-34092

Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server Options (`server.fs.deny`) can be bypass…

Fix: 3.2.7 / 4.0.5+
Fix from $1,950 2023-06-01
Gpt Academic MEDIUM 6.5
CVE-2023-33979

gpt_academic provides a graphical interface for ChatGPT/GLM. A vulnerability was found in gpt_academic 3.37 and prior. This issue affects some unknow…

Fix: 3.37+
Fix from $1,600 2023-05-31
Download Center HIGH 7.5
CVE-2023-2749

Download Center fails to properly validate the file path submitted by a user, An attacker can exploit this vulnerability to gain unauthorized access …

Fix: 1.1.5.r1298+
Fix from $1,950 2023-05-31
Rozcom Client HIGH 7.5
CVE-2023-31185EPSS 13%

ROZCOM server framework - Misconfiguration may allow information disclosure via an unspecified request.

No fix yet
Fix from $1,950 2023-05-30
Console MEDIUM 5.3
CVE-2023-33955

Minio Console is the UI for MinIO Object Storage. Unicode RIGHT-TO-LEFT OVERRIDE characters can be used to mask the original filename. This issue has…

Fix: 0.28.0+
Fix from $1,600 2023-05-30
Relevant HIGH 7.5
CVE-2014-125102

A vulnerability classified as problematic was found in Bestwebsoft Relevant Plugin up to 1.0.7 on WordPress. Affected by this vulnerability is an unk…

Fix: 1.0.8+
Fix from $1,950 2023-05-29
Requests MEDIUM 6.1
CVE-2023-32681

Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an …

Fix: 2.31.0+
Fix from $1,600 2023-05-26
Synapse MEDIUM 5.0
CVE-2022-39335

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix Federation API allows remote homeservers …

Fix: 1.69.0+
Fix from $1,600 2023-05-26
Openblue Enterprise Manager Data Collector MEDIUM 6.5
CVE-2023-2025

OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumst…

Fix: 3.2.5.75+
Fix from $1,600 2023-05-18
Agent HIGH 7.5
CVE-2022-45459

Sensitive information disclosure due to insecure registry permissions. The following products are affected: Acronis Agent (Windows) before build 3002…

Fix: 15+
Fix from $1,950 2023-05-18
Teslamate MEDIUM 5.3
CVE-2023-29857

An issue in Teslamate v1.27.1 allows attackers to obtain sensitive information via directly accessing the teslamate link.

No fix yet
Fix from $1,600 2023-05-18
Mattermost HIGH 7.5
CVE-2023-2514

Mattermost Sever fails to redact the DB username and password before emitting an application log during server initialization. 

Fix: after 7.9.1
Fix from $1,950 2023-05-12
Spectrum Virtualize MEDIUM 5.9
CVE-2023-27870

IBM Spectrum Virtualize 8.5, under certain circumstances, could disclose sensitive credential information while a download from Fix Central is in pro…

Patch available
Fix from $1,600 2023-05-11
6gk1411 1ac00 Firmware HIGH 7.5
CVE-2023-29106

A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2…

Patch available
Fix from $1,950 2023-05-09
Businessobjects Business Intelligence HIGH 7.6
CVE-2023-30740

SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is oth…

Mitigation only
Fix from $1,950 2023-05-09
Businessobjects Business Intelligence MEDIUM 5.0
CVE-2023-31404

Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420, 430, allows an attacker to …

Mitigation only
Fix from $1,600 2023-05-09
Gui For Windows CRITICAL 9.3
CVE-2023-32113

SAP GUI for Windows - version 7.70, 8.0, allows an unauthorized attacker to gain NTLM authentication information of a victim by tricking it into clic…

Fix: 7.70+
Fix from $2,300 2023-05-09